Back to skill

Security audit

USA Business Migration Planner

Security checks across malware telemetry and agentic risk

Overview

The skill appears mislabeled and may activate for ordinary requests, though it does not contain code that directly accesses or changes your system.

Review before installing. This should be renamed and scoped to the AI Studio philosophy-graph workflow, or rewritten to actually support USA business migration planning. Its generic triggers and implicit invocation should be narrowed before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (18)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill presents itself as a USA business migration planner, but the README content describes an unrelated philosophy/AI Studio workflow. This identity mismatch can misroute user requests, defeat user consent and review expectations, and allow the skill to activate in contexts where users and operators believe they are invoking a different capability.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The README presents the skill as a 'USA Business Migration Planner' while the actual documented behavior is an unrelated philosophy knowledge-graph workflow. This identity mismatch can mislead users, reviewers, and automated routing systems, making it easier for a skill to be invoked or trusted under false pretenses and obscuring its real scope.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest-described purpose and the skill's apparent identity conflict materially: a business-migration planner should not document a philosophy-graph creation workflow. This kind of semantic mismatch is dangerous because it can bypass human scrutiny, confuse permission/risk expectations, and hide repurposed or substituted skill behavior.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill is named and presented as a USA business migration planner, but its actual requirement and workflow target an unrelated philosophy graph creation task. This mismatch can cause incorrect auto-invocation, mislead users and downstream systems about the skill's purpose, and increase the chance that the wrong instructions are applied in sensitive contexts.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The document title claims one domain while the stated requirement and examples describe a completely different task. Such contradictory metadata undermines trust boundaries and can route users or agents into executing irrelevant or unsafe guidance under a misleading label.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill’s declared identity and heading indicate 'USA Business Migration Planner', but the body actually targets an unrelated generic workflow for building a philosophy graph in AI Studio. This mismatch can mislead routing, reviewers, and users, causing the skill to be invoked in the wrong context and potentially bypassing expected scrutiny for what the skill really does.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The manifest presents the skill as a 'USA Business Migration Planner' while the description and default prompt instead describe building a philosophy-themed AI Studio graph artifact. This identity/purpose mismatch is dangerous because users, routing systems, or reviewers may invoke or trust the skill under false pretenses, enabling deceptive behavior, misrouting, or policy bypass through disguised functionality.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The skill metadata says it is a USA business migration planner, but the actual requirement plan and triggers target an unrelated AI Studio philosophy-graph task. This mismatch can cause the skill to activate in the wrong context, misleading users and upstream routing logic, and may be used to smuggle unintended behavior under a trusted or unrelated label.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The documented audience, category, and usage signals describe generic online-help workflow support rather than USA business migration planning. Broad, mis-scoped targeting increases the chance the skill will be invoked for unrelated requests, creating prompt-routing confusion and enabling accidental or intentional misuse of the skill outside its declared trust boundary.

Vague Triggers

High
Confidence
94% confidence
Finding
Using broad trigger keywords like "general-help," "create," "studio," and especially "hello" makes the skill eligible for activation during ordinary conversation rather than explicit user intent. In an agent ecosystem, overbroad activation increases the chance of unintended tool invocation, prompt/context leakage into the skill, and confusing or unsafe workflow execution.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger sentence begins with the generic phrase "Help me," which is common in normal user requests and can cause ambiguous or accidental matching. This broadens the activation surface and may cause the skill to intercept unrelated tasks, especially given the already inconsistent skill identity.

Vague Triggers

High
Confidence
91% confidence
Finding
The keyword list includes generic triggers such as 'general-help', 'create', 'studio', and 'hello', which are common in normal conversation. Overbroad triggers can cause unintended activation, inappropriate context capture, or routing users into a skill they did not intend to invoke.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation examples use broad natural-language phrases that lack a clear, explicit activation boundary. This increases the chance that ordinary user requests are interpreted as skill invocations, leading to accidental execution or user confusion about what system is acting.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger set includes generic terms like 'general-help', 'create', 'studio', and 'hello', which are common in ordinary conversation. Overbroad triggers can cause frequent unintended activation, exposing users to irrelevant instructions and increasing the blast radius of the skill's already-misaligned content.

Vague Triggers

High
Confidence
97% confidence
Finding
The trigger list contains overly broad everyday terms such as 'hello', 'create', and 'general-help', which can cause accidental or excessive invocation far outside the skill’s intended scope. In an agent environment, this increases prompt-surface exposure and can let a mislabeled skill intercept unrelated conversations, amplifying the risk created by the content/identity mismatch.

Vague Triggers

High
Confidence
94% confidence
Finding
The invocation description is vague and broad, describing general help for assorted keywords rather than a clearly bounded task. Ambiguous activation criteria make unintended routing more likely, especially because the skill is already mislabeled and could be selected for requests unrelated to its actual behavior.

Vague Triggers

High
Confidence
92% confidence
Finding
The default prompt is overly broad and ambiguous, combining generic invocation language with an unrelated, open-ended task description. Ambiguous prompts increase the chance of unintended invocation, incorrect task routing, and abuse where a skill can be triggered outside its expected scope or used to smuggle unrelated instructions.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger set includes very broad terms and phrasing that overlap with normal conversation, making accidental activation likely. In the context of an already mis-scoped skill, this is more dangerous because the skill may intercept unrelated user requests and provide irrelevant or misleading guidance.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.